#VU103678 Improper error handling in Cisco IOS XR - CVE-2025-20172
Published: February 6, 2025 / Updated: May 2, 2025
Cisco IOS XR
Cisco Systems, Inc
Description
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper error handling in the SNMP subsystem. A remote authenticated user can send specially crafted SNMP versions 1, 2c, or 3 requests to the affected system and perform a denial of service (DoS) attack.
Remediation
External links
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-dos-sdxnSUcW
- https://www.zerodayinitiative.com/advisories/ZDI-25-271/
- https://www.zerodayinitiative.com/advisories/ZDI-25-272/
- https://www.zerodayinitiative.com/advisories/ZDI-25-274/
- https://www.zerodayinitiative.com/advisories/ZDI-25-273/